CYNDER · TECHNICAL ROADMAP
ONE NODE
TECHNICAL ROADMAP · ONE NODE

Finish one production node—with explicit wallet and contract authority.

This is the implementation-grade specification for the Go/Badger/x402/OCI/Kubernetes/Knative product, its IPFS evidence layer, its node identity and wallet custody, its required Base USDC dependency, and its optional evidence-anchor contract.

Current engineering goal
Finish, harden, validate, deploy, operate, and economically validate the complete one-node Cynder product, including its initial IPFS evidence-publication layer.

Current formal gate: M0 — BLOCKED

Target objectives: M3 — complete eight-action lifecycle; M7 — operational one-node IPFS evidence layer

The immediate product target remains the complete eight-action lifecycle. The deterministic evidence-block and IPFS publication subsystem is now an explicit one-node delivery milestone before release rehearsal; it is not deferred behind G-SINGLE and is not consensus.

Current evidence state

EV-SOURCE-01 · BLOCKED

Procedure: git rev-parse HEAD; git rev-parse HEAD^{tree}; git status --short

  • Pinned retrievable baseline is commit 134072ad266736c796ab7eac03679724a0af3a0f / tree c16e1769e35a2c50c60487d428c7a8a31f86cede
  • Canonical workspace also contains uncommitted explorer/statistics changes; those mutable bytes are excluded from the pinned baseline
  • M0 requires an explicit baseline acceptance decision and fresh evidence generated against that exact immutable identity

Do not mix dirty-workspace observations into evidence for the pinned commit.

EV-WORKSPACE-TEST-01 · FAILED — OBSERVATION ONLY

Procedure: make test in mutable canonical workspace

  • internal/store/explorer_stats_test.go currently fails to build because sync is imported and not used

This records in-progress workspace health only. It neither changes nor proves the pinned commit; it must be superseded by a test artifact generated from the accepted immutable baseline.

EV-LIFE-01 · PASS_WITH_LIMITATION

Procedure: make e2e-hermetic

Fixture-based and no-spend; it does not prove the planned real all-eight customer lifecycle.

EV-BASE-01 · PASS

Procedure: make generate-check

Generated parity only.

One-node product boundary

Architecture

One process

gateway + executor + embedded registry

Authority

One durable state domain

Badger + OCI files on one RWO PVC

Execution

One Knative environment

operator-controlled, invite/allowlist workload class

Evidence

One IPFS publication layer

deterministic Merkle evidence blocks + redundant retrieval + standalone verification

Wallet and contract specification

Required now

Customer EOA + Base USDC

EIP-191 actions, EIP-3009 payments, exact payer/payee/contract verification.

One-node target

Separated node authority

Stable identity manifest, evidence signer, Safe payee/treasury and admin, refund and rotation controls.

Optional gate

CynderEvidenceAnchorV1

Immutable append-only root/CID registry behind G-COMMIT-BASE.

Open the normative wallet and contract specification →

Dependency spine

M0 baseline → M1 identity/signature contract → M2 canonical data → M3 full lifecycle → [M4 failure ∥ M5 wallet/payment/custody ∥ M6 runtime security] → M7 evidence blocks/IPFS → G-IPFS → M8 operations/recovery → M9 exact release → G-PROD → M10 paid proof → G-SINGLE

Technical milestones

M0
Pinned baseline and evidence contract
BLOCKED — IMMUTABLE BASELINE ACCEPTANCE AND FRESH EVIDENCE REQUIRED
M1
Normative API, identity, and state contract
WAITING ON M0
M2
Canonical data, migration, and integrity
WAITING ON M1
M3
Complete eight-action lifecycle
TARGET OBJECTIVE — GATE ELIGIBILITY BLOCKED BY M0–M2
M4
Failure, idempotency, and recovery
WAITING ON M3
M5
Base, x402, accounting, and custody
WAITING ON M3
M6
Runtime, artifact, and workload security
WAITING ON M3
M7
One-node evidence blocks and IPFS publication
REQUIRED ONE-NODE SCOPE — WAITING ON M1–M4
M8
Observability, backup, restore, and operations
WAITING ON M4–M7
M9
Immutable release and production rehearsal
WAITING ON M8
M10
Bounded paid customer proof
CONDITIONAL ON G-PROD
Not current scope: CometBFT or validator networking; multi-node canonical state or a distributed database; permissionless providers or workloads; IPFS/P2P workload-artifact distribution (separate from required one-node IPFS evidence publication); CYNDER issuance, staking, liquidity, or governance; claims of hostile-code isolation without a separately proven sandbox and node boundary. The required executable IPFS lane is M7 evidence publication only. Base anchoring, CometBFT, validators, provider decentralization, token, staking, and governance remain outside the initial one-node scope.
SOURCE-GROUNDED ONE-NODE TECHNOLOGY

The complete one-node system

The production target is not “a process and a database.” It is the integrated Go, Badger, EIP-191, x402, Base/USDC, OCI, Kubernetes, Knative, Helm, supply-chain, deterministic evidence-block, and IPFS publication system below—operated as one operator-controlled node with separated signer and custody roles.

Truth labels matter. Implemented technology is not automatically production-proven. External prerequisites, configurable policy, mutable-workspace observations and delivery gaps remain visibly separate.

Runtime and authority map

Wallet / API clientHTTP/JSON · Idempotency-Key · EIP-191 · x402 v2
HTTPS ↓
Ingress boundaryingress-nginx · cert-manager TLS · optional public host
External payment dependenciesx402 facilitator · Base mainnet RPC · native Circle USDC
ClusterIP :8080 ↓     HTTPS / JSON-RPC ↔
cynderdone Go 1.25 binary · one pod · one process · one writer · gateway + executor + registry
HTTP action planeOpenAPI 3.1 · strict JSON · private reads · public explorer · SSE · health/readiness
Identity & admissionCAIP-10 Base wallets · EIP-191 · scopes · PENDING_REVIEW → ACTIVE
ActionEngineprepare → pay → claim → dispatch → finalize · persisted fences · UNKNOWN recovery
Payment enginex402 exact-EVM · EIP-3009 · Base receipt/event reconciliation
Embedded OCI registryDistribution v3 · /v2/ · scoped bearer tokens · manifests/blobs · retention/pins
Knative gatewaydeterministic Services/revisions · deploy/version/rollback/invoke/delete
BadgerDB v4.8canonical action, payment, receipt, deployment, version, wallet, artifact and accounting records
OCI filesystemcontent-addressed manifests and blobs · separate from Badger metadata
Kubernetes + Knative APIs ↓     one RWO PVC ↓
cynder-workloads namespaceKnative Serving 1.23 · Kourier 1.23 · service accounts · pull secrets · quotas · NetworkPolicies · mvi-small
/var/lib/cynder/badger + /registry · default 10 GiB ReadWriteOnce · quiesced VolumeSnapshot recovery
cluster-local HTTP ↓
Controlled customer workloadscale 0–2 · concurrency 1 · 500m CPU · 512 MiB RAM · 1 GiB ephemeral · non-root · read-only rootfs

Wallet and Base-contract trust boundaries

IMPLEMENTED

Customer EOA

Externally held EIP-191 action signer and EIP-3009 payer. Current code does not support ERC-1271 contract wallets.

REQUIRED EXTERNAL CONTRACT

Native Base USDC

Exact chain, address, EIP-712/EIP-3009 domain, authorization/event/receipt and code/proxy identity must be pinned.

TARGET ONE-NODE CUSTODY

Safe payee + admin

Separate 2-of-3 treasury/payee and node/contract-admin authority; neither private key enters cynderd.

OPTIONAL

Anchor signer + contract

Low-balance signer submits exact immutable evidence commitments to CynderEvidenceAnchorV1 after G-COMMIT-BASE.

Normative role, custody, ABI, lifecycle, and failure specification →

Required one-node evidence publication subsystem

Canonical Badger cutoffeligible terminal records · stable identities · deterministic coverage boundary
deterministic projection ↓
Evidence block builderREQUIRED ONE-NODE GAP
Canonical encoderversioned bytes · domain separation · privacy projection
Merkle builderstable ordering · proof reconstruction · linked block sequence
Durable publisherseal once · expected CID · retry exact bytes · quarantine conflicts
Standalone verifierno cynderd dependency · CID/root/linkage/coverage report
CAR/envelope ↓
IPFS availabilityprimary publish/pin · independent second pin or content-addressed mirror · periodic readback
Operational boundaryasynchronous evidence lag/backlog; outage never blocks customer execution
Technology

Merkle + CAR/IPFS

Versioned canonical encoding, domain-separated hashing, deterministic package bytes, CID derivation and pin/readback.

Protocol

Evidence publication

Badger cutoff → sealed envelope/CAR → expected CID → publish/pin → independent retrieval and verification.

Persistence

Canonical publication bookkeeping

Badger owns sequence, cutoff, sealed bytes, expected CID, attempts, availability observations and quarantine state.

Current truth

Not implemented

The repository has no evidence-block builder, Merkle pipeline, IPFS client/publisher, redundant pinning or standalone verifier yet.

Implemented technology stack

LayerImplemented technology
Language / processGo 1.25; net/http; JSON slog; graceful SIGINT/SIGTERM shutdown
Canonical stateBadgerDB v4.8 with synchronous writes and persisted node identity
API / projectionHTTP/JSON REST; OpenAPI 3.1; embedded public explorer; Server-Sent Events
Wallet authorityCAIP-10 eip155:8453 identities; EIP-191 personal-sign domain binding
Paymentx402 v2 exact EVM; EIP-3009 TransferWithAuthorization; Base mainnet; native USDC
Ethereum integrationgo-ethereum client, signature recovery, JSON-RPC receipt/event reconciliation
Artifact custodyDocker Distribution v3; OCI/Docker Distribution API v2; filesystem blobs
Workload controlKubernetes client-go; Knative Serving client; deterministic Service/revision identities
Packagingmulti-stage BuildKit; CGO_ENABLED=0; distroless Debian 12; non-root runtime
DeploymentHelm v3; Kubernetes ≥1.28; one Deployment/Service/PVC; ConfigMap; Secret refs; RBAC; NetworkPolicy; optional Ingress
Serverless runtimeKnative Serving 1.23 and Kourier 1.23 checksum-pinned installation assets
Release / recoveryGHCR digest pinning; GitHub Actions protected environment; keyless Cosign; Helm atomic rollout; VolumeSnapshot

Application components

HTTP API, explorer and docs

IMPLEMENTED IN PINNED BASELINE

Strict action preparation/execution, authenticated owner reads, sanitized public explorer, search/detail projections, SSE stream, /docs, /openapi.json, liveness and readiness all share the one listener.

internal/httpapi/actions.gointernal/httpapi/pages.gointernal/httpapi/explorer_stream.goapi/openapi.yaml

Wallet enrollment and admission

IMPLEMENTED · NOT PRODUCTION-PROVEN

Canonical Base wallet identity and owner→tenant mapping. Enrollment is durable and scoped: PENDING_REVIEW → APPROVED_INACTIVE → ACTIVE. Review and activation are separate operator authorities; enrollment never auto-activates x402 access.

internal/store/wallet_enrollment.gocmd/cynderd/main.go

ActionEngine and recovery

IMPLEMENTED · HARDENING REQUIRED

Durable two-phase lifecycle with bounded in-process serialization, payment gating, persisted dispatch fences, action-specific projection commits and digest-linked receipts. Ambiguous post-dispatch effects become UNKNOWN; ambiguous INVOKE is not automatically retried.

internal/platform/action_engine.gointernal/httpapi/actions.gointernal/store/action_store.go

x402, Base and USDC

IMPLEMENTED · OPERATING POLICY INCOMPLETE

x402 v2 exact-EVM on Base mainnet binds signer, payer, payee, native USDC asset, amount and immutable action. Facilitator response is not finality: Base authorization state, events, transfer and transaction receipt are reconciled independently.

internal/payment/action_x402.gointernal/payment/action_x402_reconcile.go

Registry authentication and OCI custody

IMPLEMENTED · PROVENANCE/GC GAPS

Distribution v3 serves /v2/. Basic credentials exchange for HMAC-SHA256 short-lived tenant/repository/action-scoped bearer tokens. Deterministic rotatable pull credentials feed immutable Kubernetes image-pull secrets. Admission hashes manifests/blobs and requires Linux/amd64.

internal/auth/auth.gointernal/registry/registry.gointernal/store/artifact_store.go

Kubernetes / Knative execution

IMPLEMENTED · TARGET-CLUSTER PROOF REQUIRED

Deterministic Knative Services and revisions run cluster-local in a distinct workload namespace. Cynder creates service accounts, immutable pull secrets, quotas and NetworkPolicies; reconciles readiness; proxies invocation; activates versions; rolls back; and confirms deletion.

internal/runtime/knative.gointernal/gateway/action_executor.gocharts/cynder/templates/rbac.yaml

Canonical Badger state

IMPLEMENTED · DATA CONTRACT HARDENING REQUIRED

One synchronous-write database owns immutable actions, mutable lifecycle state, payment fingerprints/bindings, sequenced receipt chains, deployment/version state, wallet enrollments, artifacts, retention/pins, registry accounting, recovery schedules and node identity.

internal/store/action_store.gointernal/store/deployment_versions.gointernal/store/wallet_enrollment.gointernal/store/artifact_store.go

Release, supply chain and recovery

IMPLEMENTED FOUNDATIONS · DR PROOF INCOMPLETE

Digest-pinned GHCR control image, protected GitHub deployment environment, keyless Cosign verification, Helm --atomic --wait, post-deploy checks, image-only rollback and quiesced CSI VolumeSnapshot tooling. Replacement-PVC restore and recurring recovery drills remain unproved.

.github/workflows/deploy.ymlDockerfilehack/deploy.shhack/backup-volume-snapshot.shhack/rollback.sh

Configuration and secret custody

CONFIGURABLE · OPERATOR-OWNED

ConfigMap carries non-secret runtime policy. Existing Kubernetes Secret references supply Base RPC and registry credential material. The pod uses a projected expiring service-account token; the roadmap names secret references only, never values.

charts/cynder/templates/config.yamlcharts/cynder/templates/deployments.yamlcharts/cynder/values.yaml

Observability and operator control

PARTIAL · DELIVERY GAP

JSON logs, health/readiness, public projections and release verification exist. Production still requires correlation-complete metrics/traces, ambiguity and reconciliation alerts, SLOs, capacity alarms, incident freeze controls and recurring operational evidence.

cmd/cynderd/main.gointernal/httpapi/actions.gohack/verify-deployment.sh

Protocol surface

BoundaryProtocol and binding
Action APIHTTPS + JSON; Idempotency-Key; CYNDER-ACTION-DIGEST; CYNDER-ACTION-SIGNATURE
Wallet identityCAIP-10 eip155:8453:0x… plus EIP-191 personal-sign authority
Payment challengex402 v2 PAYMENT-REQUIRED / PAYMENT-SIGNATURE / PAYMENT-RESPONSE
USDC transferEIP-712 typed data + EIP-3009 TransferWithAuthorization
Settlement truthBase HTTPS JSON-RPC; nonce, AuthorizationUsed event, transaction receipt and exact Transfer reconciliation
Artifact APIOCI / Docker Distribution v2 at /v2/; Basic exchange → short-lived scoped bearer token
Runtime controlKubernetes REST + Knative Serving API; SelfSubjectAccessReview before readiness
InvocationCluster-local HTTP POST; X-Cynder-Invocation-ID + Idempotency-Key
Operations/healthz, /readyz, /registry/readyz; explorer SSE at /v1/explorer/stream

Canonical state and persistence

The authoritative state must be derivable from explicit durable records and transitions—not process memory, UI state or whatever Kubernetes happens to report.

State classContents and authority
Canonical Badger recordsactions; action-state; action identity; payments; payment fingerprints; action-payment bindings; receipts; invocation replay; deployments; versions; activations; delete claims/tombstones; wallet enrollment; artifacts; pins; registry accounting; node and index metadata
Canonical OCI bytesmanifests, configs and layers under /var/lib/cynder/registry; content addressed but not stored as Badger values
Derived / rebuildableexplorer/search indexes and aggregate projections; never the authority for action/payment/runtime truth
External observationsKubernetes and Knative object/status observations; reconciled effects, not canonical Cynder state
Ephemeral onlyprocess locks, HTTP request state, caches and transient worker state; never sufficient to prove a durable transition
Backup unitthe quiesced shared PVC containing /badger and /registry, bound to the persisted node/PVC identity

Action state machine

PREPARE:  strict payload → owner/scope admission → immutable canonical action → PENDING / UNPAID → ACCEPTED receipt
AUTHORIZE: EIP-191 route+origin+digest authority → owner recheck
PAY:       x402/EIP-3009 proof → durable reservation → facilitator verify/settle → Base reconciliation → SETTLED receipt
EXECUTE:   claim → EXECUTING receipt → durable DISPATCHED fence → runtime/registry/wallet effect
FINALIZE:  projection commit → SUCCEEDED or FAILED → digest-linked terminal receipt
AMBIGUOUS: post-dispatch uncertainty → UNKNOWN → bounded reconciliation; never blind INVOKE replay
Independent domains: intent ≠ authorization ≠ admission ≠ payment verification ≠ settlement/finality ≠ execution attempt ≠ effect outcome ≠ receipt persistence ≠ reconciliation.

Eight-action customer lifecycle

ENROLL_WALLET → PENDING_REVIEW → independent review → APPROVED_INACTIVE → independent activation → ACTIVE
→ REGISTER_ARTIFACT → DEPLOY → INVOKE v1 → DEPLOY_VERSION → INVOKE v2
→ ROLLBACK_VERSION → INVOKE rolled-back v1 → RETAIN_ARTIFACT → DELETE
→ Knative runtime absent + durable deployment tombstone + preserved action/payment/receipt/version/artifact history
ActionTechnology pathDurable result
ENROLL_WALLETHTTP/JSON → CAIP-10 owner → scoped enrollment storePENDING_REVIEW; no automatic paid access
REGISTER_ARTIFACTOCI v2 → tenant bearer auth → manifest/blob hash and limitsAPPROVED immutable artifact record; signature/vulnerability NOT_CHECKED today
RETAIN_ARTIFACTowned repository@digest → retention validatorabsolute retention deadline; replay cannot extend twice
DEPLOYsettled x402 → ActionEngine → registry proof → Knative Servicedeployment + initial immutable version + readiness + artifact pin
DEPLOY_VERSIONsigned source tag resolves to signed digest → Knative revisionnew immutable version; active pointer moves only after readiness
ROLLBACK_VERSIONstored version identity → exact Knative image/revision reconcilerollback activation; prior history remains append-only
INVOKEcluster-local HTTP + invocation/action idempotency headersbounded persisted output/receipt, or UNKNOWN if response is ambiguous
DELETEdelete claim → UID/label-owned Knative removal → pin releaseruntime absence + atomic durable tombstone and terminal receipt

Deployment object model

Platform namespace

  • one Kubernetes Deployment; replicas=1; strategy=Recreate
  • one cynderd container and ClusterIP Service on :8080
  • one 10 GiB-default ReadWriteOnce PVC
  • ConfigMap, existing Secret references, ServiceAccount, namespaced Role/RoleBinding
  • optional TLS Ingress through ingress-nginx/cert-manager
  • digest-pinned external GHCR control image—never the embedded registry

Workload namespace

  • deterministic, cluster-local Knative Services and revisions
  • per-owner service accounts and immutable pull secrets
  • ResourceQuota plus default-deny NetworkPolicies
  • mvi-small: 500m CPU, 512 MiB RAM, 1 GiB ephemeral storage
  • scale-to-zero, max scale 2, concurrency 1, 300-second bound
  • startup SelfSubjectAccessReview proves required namespaced permissions

Security boundary

Implemented controls

  • HTTPS/control-origin binding and EIP-191 domain separation
  • payer must equal action signer; payment evidence binds one action
  • strict JSON, body/header/rate and unpaid-action limits
  • immutable OCI digest authority plus repository allowlist
  • tenant-scoped registry repositories/tokens/pull credentials
  • namespaced RBAC; no cluster-wide workload or Secret authority
  • platform/workload service-account separation; token automount disabled
  • cluster-local Knative visibility and default-deny workload networking
  • non-root, no privilege escalation, dropped capabilities, read-only rootfs, RuntimeDefault seccomp
  • fixed CPU/memory/ephemeral limits and bounded runtime
  • UID/label ownership checks before runtime deletion
  • digest-pinned control image, protected deployment environment and keyless Cosign release verification
  • sanitized fixed public explorer projections; no administrative delete API

Must close before broader production

  • workload Cosign/provenance enforcement
  • vulnerability admission policy
  • reference-safe registry garbage collection
  • proof that the selected CNI enforces policies
  • sandbox RuntimeClass and isolated nodes before hostile workloads
  • recurring backup/restore and incident drills
  • production metrics, tracing, alerts and capacity evidence

Current admitted posture: controlled, reviewed workloads. Shared-kernel execution is not proof of a hardened hostile multi-tenant sandbox.

External prerequisites and failure boundaries

Cluster substrate

Kubernetes ≥1.28, Knative Serving 1.23, Kourier 1.23, CSI snapshot support; ingress-nginx and cert-manager when publicly exposed.

Payment substrate

HTTPS x402 facilitator, trusted Base mainnet RPC, native Circle USDC and operator-controlled payTo/custody. Each can fail independently of action execution.

Supply chain

GHCR candidate image, protected GitHub environment, keyless Cosign identity, exact chart/config/environment. Mutable tags are never execution or release authority.

Not claimed: horizontal control-plane scaling, Byzantine consensus, hostile-code isolation, exactly-once invocation, independent-provider receipts, a decentralized network, or any token/staking/governance system.
ORDERED IMPLEMENTATION PATH

M0–M10 technical milestones

Implementation-grade gates now bind wallet roles, contract identities, custody, rotation, failure semantics, evidence, and release identity—not merely code presence.

M0
BLOCKED — IMMUTABLE BASELINE ACCEPTANCE AND FRESH EVIDENCE REQUIRED

Pinned baseline and evidence contract

Freeze the exact source, release, environment, state authorities, and evidence schema used by every later claim.

depends: none
Deliverables
  • one-node topology and bill of materials
  • all-eight action/transition matrix
  • release identity manifest: source, image, chart, config, node, environment, Kubernetes, Knative, Base/USDC, facilitator, RPC
  • evidence record schema and known-nonclaims register
  • wallet-role and contract inventory: supported customer wallet type, node ID, payee, treasury/refund/admin/evidence/anchor/pauser roles, chain IDs, contract addresses, runtime code/proxy identities, and current nonclaims
Acceptance
  • Exactly eight actions agree across Go source and OpenAPI
  • Each transition names its authority and persistence point
  • Every claim is source-backed, evidence-backed, or visibly unproved
  • Pinned baseline proves no node wallet or Cynder-authored contract currently exists and identifies Base USDC as an external dependency
Verification and stop
  • make generate-check
  • make test

Stop: Stop if source/OpenAPI disagree, release identity is incomplete, or payment/effect/receipt states collapse into one success field.

M1
WAITING ON M0

Normative API, identity, and state contract

Make the existing one-node state machines and idempotency guarantees explicit and machine-testable.

depends: M0
Deliverables
  • versioned canonical encodings and golden digest/receipt vectors
  • state-transition and terminality specification
  • stable error/retry taxonomy
  • public/private data classification
  • normative EOA-only customer signature contract, exact EIP-191 replay domain, node identity manifest schema, wallet-role matrix, and external-contract identity rules
Acceptance
  • Signatures fail closed across wrong origin, method, route, owner, action, or digest
  • Payment fingerprint cannot bind two actions
  • Every error classifies retry as safe, delayed, unsafe, or operator-gated
  • Receipt mutation/reordering is detected
  • Contract wallets fail explicitly until ERC-1271 is separately implemented; customer signer equals x402 payer
Verification and stop
  • go test ./internal/model ./internal/auth ./internal/payment ./internal/store
  • make acceptance
  • cross-language EIP-191 and node-manifest canonicalization/signature vectors

Stop: Stop if any consequential transition depends only on process memory or HTTP response delivery.

M2
WAITING ON M1

Canonical data, migration, and integrity

Make Badger plus the registry volume a clean, recoverable authority rather than an accidental collection of local records.

depends: M1
Deliverables
  • Badger keyspace/data dictionary and explicit schema version
  • ordered migration framework and compatibility policy
  • full integrity scanner for node ID, actions, payments, receipts, deployments, versions, artifacts, pins, tombstones
  • derived-index rebuild procedure and retention policy
Acceptance
  • Clean open, same-version reopen, supported upgrade, interruption recovery, and restore behave explicitly
  • Node mismatch and canonical corruption block readiness/mutation
  • Derived indexes rebuild without changing canonical records
  • UNKNOWN and payment-ambiguous records survive migration/restore
Verification and stop
  • go test ./internal/store ./internal/registry
  • fault-injected migration and corruption suite

Stop: Stop on partial migration without a deterministic resume/restore path, broken receipt chain, or irreconcilable canonical reference.

M3
TARGET OBJECTIVE — GATE ELIGIBILITY BLOCKED BY M0–M2

Complete eight-action lifecycle

Prove the product as one coherent customer journey through the public/control boundary, not eight isolated handlers.

depends: M2
Deliverables
  • hermetic all-eight HTTP lifecycle suite
  • real Kubernetes/Knative cluster lifecycle suite with non-paying fixture
  • guarded real-payment lifecycle harness
  • per-step expected canonical/runtime/readback fixture
  • customer and operator lifecycle runbook
  • all-eight lifecycle proof using the supported customer EOA type and exact payer/payee bindings
Acceptance
  • Empty-state journey completes without direct DB edits or Kubernetes repair
  • Every paid success has one settlement binding and valid terminal receipt
  • Version/rollback select exact immutable digest and runtime revision
  • Replay causes no second charge or effect
  • Delete removes only managed runtime and retains tombstone/history
Verification and stop
  • make e2e-hermetic
  • guarded cluster lifecycle: enrollment → approval/activation → register → deploy → invoke v1 → deploy version → invoke v2 → rollback → invoke v1 → retain → delete

Stop: Stop if an action works only in isolation, ownership/scope is bypassable, or active version, digest, runtime revision, and receipt disagree.

M4
WAITING ON M3

Failure, idempotency, and recovery

Define and prove the recovery rule at every money/effect ambiguity boundary without claiming exactly once.

depends: M3
Deliverables
  • operation guarantee matrix
  • persisted execution fences and bounded recovery policy
  • fault-injection harness at payment, dispatch, effect, response, state, and receipt boundaries
  • UNKNOWN/operator-resolution view and append-only decision record
  • refund eligibility and duplicate-refund controls
  • signing ambiguity, nonce/replacement, payee-rotation overlap, signer outage/compromise, stale restore, and contract-drift failure semantics
Acceptance
  • No injected crash duplicates a charge, deploy, version activation, delete, refund, or receipt
  • UNKNOWN invoke is never automatically dispatched again
  • Recovery is bounded by persisted attempt count, age, and backoff
  • Settlement ambiguity resumes/reconciles the same operation instead of submitting another
Verification and stop
  • go test ./internal/platform ./internal/payment ./internal/httpapi
  • kill-point matrix before/after settlement, dispatch, effect, response, and receipt append

Stop: Stop on duplicate consequential effect, invisible recovery backlog, unsafe automatic retry, or evidence-destructive manual status edit.

M5
WAITING ON M3

Base, x402, node wallet, accounting, and custody

Make real payment safe enough for bounded spend and daily reconciliation.

depends: M3
Deliverables
  • pinned Base/USDC/facilitator/RPC/payTo operating manifest
  • finality and reorg policy
  • quoted/reserved/settling/settled/final/unknown/refund liability ledger
  • daily chain reconciliation report
  • custody and key-rotation matrix
  • refund dual-control and spend-cap runbooks
  • adopted wallet-role matrix, JCS/SHA-256 node identity manifest, independently pinned genesis digest, and startup role-binding checks
  • externally custodied Base Safe 2-of-3 x402 payee/treasury and separate admin authority; no treasury/admin key in cynderd
  • Base USDC address, EIP-712/EIP-3009 domain, ABI, proxy/implementation or runtime-code identity, and drift verification
  • payee rotation with bounded old-authorization reconciliation and no redirect
  • refund intent, dual-approval Safe execution, original-payer binding, and duplicate-prevention contract
Acceptance
  • Wrong network, asset, payer, payee, amount, action, or signer fails before effect
  • Base evidence—not facilitator response alone—permits the accepted final state
  • Daily ledger has zero unexplained variance
  • Settlement ambiguity reserves liability
  • Credential rotation and refund paths expose no secret and cannot duplicate
  • Runtime payee differs from signed active manifest payee only by failing paid readiness
  • Customer, evidence, anchor, node-admin, and pauser keys are distinct; treasury and refund are intentionally one dual-approval Safe policy; admin may invoke pause only through its separate higher authority, never through the pauser key
Verification and stop
  • guarded real-spend canary with explicit cap
  • reorg/finality simulation
  • daily chain-to-action-to-ledger reconciliation
  • wallet-role separation, identity-manifest rotation/revocation, USDC contract drift, payee rotation, and refund-reconciliation suite

Stop: Stop on wrong binding, unexplained variance, duplicate transfer/refund, reorg-invalid evidence, custody uncertainty, or spend-cap breach.

M6
WAITING ON M3

Runtime, artifact, and workload security

Prove the admitted workload class matches the isolation the one-node platform actually provides.

depends: M3
Deliverables
  • one-node threat model and admitted-workload policy
  • Cosign/provenance and vulnerability policy enforcement
  • reference-aware retention/GC with interruption recovery
  • CNI-verified ingress/egress policy
  • RBAC, service-account, seccomp, capabilities, rootfs, quota, and capacity evidence
  • deletion/privacy/supply-chain incident contract
Acceptance
  • Mutable tags never become execution authority
  • Cross-owner access fails at API, store, registry, runtime labels, and network boundaries
  • Workloads cannot reach platform credentials or Kubernetes authority
  • Active pins survive retention/GC
  • No unresolved critical security finding
Verification and stop
  • make helm-lint
  • runtime security and tenant-isolation suite on target cluster
  • image/SBOM/signature/vulnerability verification

Stop: Stop on secret leakage, cross-tenant access, mutable artifact execution, unrestricted egress, privilege escape, or isolation weaker than admitted workload.

M7
REQUIRED ONE-NODE SCOPE — WAITING ON M1–M4

One-node evidence blocks and IPFS publication

Make externally retrievable, independently verifiable evidence a built-in property of one-node Cynder before release rehearsal, without making IPFS canonical or putting it in the execution-critical path.

depends: M1, M2, M3, M4
Deliverables
  • normative canonical evidence projection and byte-level encoding specification
  • transactionally consistent Badger cutoff and eligibility cursor
  • versioned domain-separated Merkle tree with golden vectors and deterministic odd-leaf/duplicate rules
  • durable linked evidence-block records and seal-once publication state machine
  • deterministic CAR/envelope creation, expected CID derivation, IPFS publication, pinning, and independent readback
  • standalone verifier that requires no cynderd API access
  • privacy fixtures, publication backlog controls, evidence-lag SLO, alternate pin/mirror policy, and outage/recovery runbook
  • documented compatibility boundary for a possible later Base root/CID anchor; no Base contract, transaction writer, or canary is required to close M7
  • signed evidence envelope binding node ID, identity epoch, current manifest digest, evidence key ID, block sequence, previous envelope, body CID, Merkle root, and leaf count
  • implementation-independent AnchorInput and anchor-ID golden vectors for later CynderEvidenceAnchorV1 without requiring deployment
Acceptance
  • Identical canonical records produce byte-identical leaves, Merkle root, envelope bytes, and CID across restarts
  • A stable cutoff proves which eligible terminal records are included and exposes gaps without claiming unsupported non-membership
  • No secrets, signatures, payment authorizations, private inputs/outputs, or prohibited customer metadata enter public evidence
  • Independent retrieval from a separately controlled pin or mirror reproduces the expected CID and Merkle root
  • Crash at every seal/publish/persist boundary resumes the same node/sequence and exact bytes without omission or equivocation
  • IPFS unavailability never blocks action admission, payment, execution, receipt persistence, recovery, or customer operation
Verification and stop
  • golden canonicalization, leaf, Merkle, envelope, and CID vectors
  • fault-injected seal/publish/readback recovery suite
  • independent verifier against an externally retrieved canary CAR/envelope
  • privacy corpus and forbidden-field scan
  • primary-IPFS outage plus alternate-pin retrieval drill

Stop: Stop the publication lane on nondeterministic bytes/root/CID, privacy leakage, conflicting node/sequence commitment, missing eligible-record coverage, unavailable alternate evidence, unbounded backlog, or production-path impact. Preserve canonical Badger history and quarantine conflicting evidence; do not stop customer execution solely because IPFS is unavailable.

M8
WAITING ON M4–M7

Observability, backup, restore, and operations

Operate one node, including its asynchronous evidence publisher, without reading raw Badger and recover it without losing canonical or sealed evidence.

depends: M4, M5, M6, M7
Deliverables
  • structured correlation IDs, metrics, traces, dashboards, and redaction tests
  • alerts for payment/effect ambiguity, recovery age, receipt failure, readiness, reconciliation variance, capacity, dependency outages, and security drift
  • quiesced backup schedule/retention and isolated Kubernetes PVC restore runbook
  • upgrade, rollback, disaster recovery, dependency-outage, incident-freeze, and signer-recovery runbooks
  • adopted SLO/RPO/RTO and capacity limits
  • IPFS publication backlog, pin availability, CID readback, and evidence-lag dashboards/alerts
  • wallet/signer/Safe/contract/nonce/balance/anchor-backlog/drift observability and recovery runbooks
Acceptance
  • Injected failures fire actionable alerts tied to action/release
  • Operator distinguishes payment, execution, runtime, receipt, and reconciliation state
  • Real VolumeSnapshot restore preserves node ID, payments, receipts, artifacts, versions, and tombstones
  • Restore mismatch keeps readiness false and mutation disabled
  • Telemetry contains no credentials, signatures, payment payloads, or private customer inputs
  • IPFS outage leaves admission/payment/execution/receipts healthy while publication state remains durable and observable
Verification and stop
  • hack/backup-volume-snapshot.sh plus isolated restore drill
  • hack/verify-deployment.sh
  • dependency-outage and alert-delivery exercises

Stop: Stop on monitoring blindness, failed restore, stale backup beyond RPO, broken alert delivery, or telemetry leakage.

M9
WAITING ON M8

Immutable release and production rehearsal

Produce one exact release that can be approved as tested or rejected without ambiguity.

depends: M8
Deliverables
  • digest-pinned cynderd image, chart, config, and environment manifest
  • rendered deployment packet and secret-reference inventory
  • SBOM/vulnerability/provenance evidence
  • clean install, upgrade, failed rollout, rollback, backup/restore, outage, rotation, cap, and freeze rehearsal
  • independent technical review and G-PROD activation packet
  • exact evidence format, IPFS endpoint/pinning policy, and verifier release identities
  • exact release wallet-contract manifest: active node manifest digest, public role key IDs, payee, Safe/admin/pauser identities, Base USDC identity, optional anchor contract/code/ABI/finality policy
Acceptance
  • One replica, Recreate, one RWO PVC, correct node ID, HTTPS origin, and no control-image registry circularity
  • All evidence names the exact release/environment
  • Rollback or restore is executable by an operator other than implementer
  • No critical custody/security blocker
  • Pilot caps and stop controls are configured, not prose
  • A verifier outside Cynder retrieves a published evidence block and reproduces its CID and Merkle root
Verification and stop
  • make lint && make acceptance && make helm-lint && make e2e-hermetic
  • target-cluster rehearsal against exact image/chart/config digests

Stop: Stop when running bytes/config differ from reviewed evidence, rollback/restore cannot execute, or any critical blocker remains.

M10
CONDITIONAL ON G-PROD

Bounded paid customer proof

Collect real technical, operational, customer, and economic evidence from one bounded paid workload.

depends: M9, G-PROD
Deliverables
  • named customer/workload/release activation record
  • paid happy-path and controlled failure traces
  • per-action latency/resource/storage/egress/Base/x402/support/refund/dispute cost ledger
  • SLO/incident/reconciliation report
  • repeat-use and centralized-alternative comparison
  • G-SINGLE decision packet
  • published one-node evidence blocks and independent verification report for the bounded customer window
  • pilot reconciliation from customer payer through original payee, treasury balance, refund status, evidence signer, and any separately enabled anchors
Acceptance
  • No duplicate effects/charges and no lost canonical evidence
  • 100% daily ledger reconciliation during pilot
  • Critical alerts are delivered and acknowledged
  • RPO/RTO stay within adopted bounds
  • Customer repeats use for a recorded reason and costs/support burden are measured
  • Every eligible terminal receipt in the pilot window is covered by a published, independently retrievable evidence block
Verification and stop
  • guarded real lifecycle under explicit spend/customer/workload/time caps
  • post-pilot accounting, security, operations, and customer evidence review

Stop: Contain on any global stop condition; close pilot at its explicit end even if healthy.

COMPONENT DELIVERY LANES

Fifteen one-node components

C14 and C15 make node identity/wallet custody and Base contract integration first-class technical ownership lanes.

C01 · API and protocol contract M0–M1

Current baseline: Implemented; production contract proof incomplete

Required delta: Pin canonical schemas, encodings, state machines, errors, generated parity, and conformance.

Surfaces: internal/model/action.gointernal/httpapi/actions.goapi/openapi.yaml

C02 · Customer EOA identity and enrollment M1 · M3

Current baseline: Durable enrollment + dual control exist; general operator surface/runbook incomplete

Required delta: Prove signer domain, owner/scope checks, review/activation separation, revoke/rotation, and lifecycle composition. Keep node roles unreachable from customer enrollment and label ERC-1271 unsupported until implemented.

Surfaces: internal/auth/auth.gointernal/payment/action_x402.gointernal/store/wallet_enrollment.go

C03 · Action state, attempts, and receipts M1–M4

Current baseline: Substantial implementation; needs explicit contract/integrity/operator resolution

Required delta: Assign every transition, fence effects, preserve UNKNOWN, validate receipt chains, and expose safe operator decisions.

Surfaces: internal/platform/action_engine.gointernal/store/action_store.gointernal/model/action.go

C04 · x402 and external Base USDC settlement M4–M5

Current baseline: Verification/settlement/reconciliation foundations exist; production finality/refund/accounting policy incomplete

Required delta: Prove exact binding, finality/reorg behavior, liabilities, refunds, daily reconciliation, custody, and spend caps. Pin and verify exact USDC contract/proxy identity and original-payee rotation semantics.

Surfaces: internal/payment/action_x402.gointernal/payment/action_x402_reconcile.go

C05 · OCI artifact lifecycle M3 · M6

Current baseline: Registry, registration, retention metadata, limits, and pins exist; signature/vulnerability enforcement and GC missing

Required delta: Enforce provenance, safe retention/GC, accounting integrity, tenant auth, interruption recovery, and active-pin protection.

Surfaces: internal/registry/registry.gointernal/store/artifact_store.go

C06 · Deploy, version, rollback, delete M3–M4 · M6

Current baseline: Implemented with immutable versions/tombstones; requires real-cluster and fault proof

Required delta: Prove stable runtime identity, readiness-gated activation, convergence after crash, exact rollback, and tombstoned delete.

Surfaces: internal/gateway/action_executor.gointernal/runtime/knative.gointernal/store/deployment_versions.go

C07 · Invocation and result replay M3–M4

Current baseline: Persisted replay and UNKNOWN behavior exist; customer-side effect contract/operator resolution incomplete

Required delta: Prove no automatic reinvoke after ambiguity, persisted output replay, response limits/privacy, and action-ID propagation.

Surfaces: internal/gateway/action_executor.gointernal/platform/action_engine.go

C08 · Explorer and operational projections M1 · M7–M8

Current baseline: Sanitized explorer/SSE/stats exist; operator observability is insufficient

Required delta: Keep public data minimal while adding authorized operational views for ambiguity, recovery, reconciliation, and evidence.

Surfaces: internal/httpapi/explorer_stream.gointernal/store/explorer_search.gointernal/store/explorer_stats.go

C09 · Helm, ingress, RBAC, NetworkPolicy M6 · M9

Current baseline: Single-replica packaging and safety checks exist; target-environment proof required

Required delta: Prove exact immutable release, TLS/origin, CNI policy, least privilege, resource bounds, upgrade, and rollback.

Surfaces: charts/cynderhack/deploy.shhack/verify-deployment.sh

C10 · Backup, restore, migration, DR M2 · M8–M9

Current baseline: Snapshot helper and hermetic restore tests exist; real replacement-PVC restore and migration framework incomplete

Required delta: Prove schema compatibility, quiesced snapshots, isolated restore, integrity checks, RPO/RTO, rollback/restore decision, and drills.

Surfaces: hack/backup-volume-snapshot.shhack/rollback.shinternal/registry/backup_restore_acceptance_test.go

C11 · Telemetry, SLOs, capacity, incidents M8–M10

Current baseline: Health/readiness and JSON logs exist; metrics/traces/alerts/SLO evidence largely missing

Required delta: Instrument every boundary, redact secrets, adopt thresholds, alert on ambiguity/capacity/outages, and measure pilot SLOs.

Surfaces: cmd/cynderd/main.gointernal/httpapi/actions.go

C12 · Lifecycle, pilot, and economics evidence M3 · M9–M10

Current baseline: Partial lifecycle tests exist; full eight-action real/product/economic proof missing

Required delta: Compose all eight actions, bind evidence to release/environment, and measure every action cost, liability, support burden, and customer outcome.

Surfaces: internal/httpapi/lifecycle_e2e_test.gohack/e2e.sh.github/workflows/deploy.yml

C13 · Evidence blocks, IPFS publication, and independent verification M1–M4 · M7–M10

Current baseline: Not implemented; required one-node delivery scope

Required delta: Specify canonical public evidence bytes, seal linked Merkle blocks, persist publication state, publish/pin exact IPFS content, independently retrieve and verify it, prove privacy and completeness boundaries, and keep failures asynchronous to customer execution.

Surfaces: internal/evidence (new)internal/store/evidence_blocks.go (new)internal/ipfs (new)cmd/cynder-verify-evidence (new)charts/cynder

C14 · Node identity, wallet, treasury, and signing custody M0–M5 · M7–M10

Current baseline: Stable node label and configured payTo exist; formal cryptographic binding/custody does not

Required delta: Implement the signed manifest chain, separated evidence/anchor/payee/admin/pauser/refund roles, startup binding, rotation/revocation, anti-fork restore, and public non-secret status.

Surfaces: internal/store/action_store.gointernal/identity (new)internal/signing (new)charts/cynderoperator custody manifests/runbooks

C15 · Base contracts and optional evidence anchor M0 · M5 · M7–M10 · G-COMMIT-BASE

Current baseline: Native Base USDC integration exists; no Cynder contract

Required delta: Pin external USDC identity; specify/test/deploy the optional immutable append-only anchor contract, bounded submitter, event/head indexer, signer rotation, pause, finality/reorg handling, and independent verification.

Surfaces: internal/paymentcontracts/CynderEvidenceAnchorV1.sol (new optional)internal/anchor (new optional)cmd/cynder-verify-evidencedeployment manifest

CLAIM → PROCEDURE → ARTIFACT → REVIEW

Verification and failure semantics

Wallet roles, contract identity, signer custody, rotation, chain truth, and refund/anchor ambiguity now have named evidence contracts and containment rules.

Evidence contracts

IDClaimProcedureExpectedGateFreshness
EV-BASE-01Source/OpenAPI paritymake generate-checkNo diff or stale generated artifactM0/C01every candidate
EV-UNIT-01Go package behaviormake testAll packages pass on pinned sourceM0–M9every candidate
EV-ACC-01Contract and acceptance suitemake acceptanceAll acceptance assertions passM1–M9every candidate
EV-HELM-01Rendered chart safetymake helm-lintChart renders and policy checks pass for exact valuesM6/M9every chart/config change
EV-LIFE-01All-eight hermetic lifecyclemake e2e-hermeticComplete journey and per-step readback pass from empty stateM3every candidate
EV-LIFE-02Target-cluster lifecycleguarded cluster procedureReal Knative/registry lifecycle passes against named environmentM3/M9every candidate/environment
EV-FAIL-01Crash and ambiguity matrixfault-injection suiteNo duplicate effects; expected UNKNOWN/reconciliation states persistM4every effect/payment change
EV-PAY-01Bounded real USDC traceguarded real-spend procedureExact Base evidence reconciles to action, receipt, and ledger under capM5/M9before pilot and each payment change
EV-SEC-01Runtime and tenant securitytarget-cluster security suiteIsolation, CNI policy, RBAC, secrets, provenance, and resource bounds passM6/M9every runtime/policy change
EV-RESTORE-01Real isolated restoreVolumeSnapshot restore drillReplacement PVC restores complete canonical state within adopted RPO/RTOM8/M9before pilot; recurring during operation
EV-OPS-01Alerts and outage behaviorinjected dependency/outage drillExpected alert, containment, recovery, and evidence are recordedM8/M9before pilot and each alert/runbook change
EV-REL-01Exact release rehearsalrelease rehearsal packetInstall/upgrade/fail/rollback/restore/rotate/freeze pass on exact digestsM9/G-PRODeach candidate
EV-PILOT-01Paid operated-product proofbounded pilot evidence packetSLO, traces, reconciliation, cost, support, repeat use, and incidents reviewedM10/G-SINGLEpilot close
EV-COMMIT-01Deterministic block, Merkle, and CID vectorscross-run golden vector suiteIdentical eligible records produce identical ordered leaves, root, envelope bytes, and expected CID; mutation, omission, duplication, and reordering are detectedM1/M2/M7every evidence-format change
EV-COMMIT-02IPFS round trip and availabilitypublish exact canary bytes; retrieve through independent endpoint/pinRetrieved bytes match expected CID and reproduce the Merkle root through at least two availability pathsM7/G-IPFSevery release and recurring operation
EV-COMMIT-03Optional Base anchor and reorg verificationseparately authorized bounded anchor canaryExact node/sequence/root/CID commitment reaches adopted finality; reorg cannot rewrite canonical or sealed historyG-COMMIT-BASEbefore activation and each anchor change
EV-COMMIT-04Crash and ambiguity recoveryfault injection at cutoff, serialize, seal, publish, CID-persist, and readback boundariesRecovery resumes identical bytes and one logical node/sequence without omission, duplicate publication identity, or conflicting rootM7every publication-state change
EV-COMMIT-05Independent evidence verificationstandalone verifier starts from CID and retrieved bytes without cynderd accessVerifier validates schema/linkage, reconstructs leaves/proofs, and reproduces the expected root while exposing coverage boundariesM7/M9/M10every release and pilot window
EV-COMMIT-PRIVACYPublic evidence privacy boundaryforbidden-field fixture corpus plus serialized-object scanNo secrets, authorizations, private inputs/outputs, credentials, or prohibited customer metadata enter IPFS objectsM7/G-IPFSevery projection/schema change
EV-WALLET-01Customer signer contract and replay domaincross-language EIP-191 vectors plus EOA/contract-wallet negative fixturesOnly the exact supported EOA, origin, method, route, action, idempotency key, and digest verify; ERC-1271 fails explicitlyM1/G-WALLET-CONTRACTevery signing-contract change
EV-WALLET-02Node role and custody separationmanifest/runtime/custody inventory plus key/account collision testsEvidence, anchor, payee/treasury, admin, pauser, refund, and customer roles are independently bound; no treasury/admin key is in cynderdM5/G-WALLET-CONTRACTevery role/config/release change
EV-WALLET-03Rotation, revocation, compromise, and restoreplanned and emergency evidence/anchor/payee/admin rotation drills plus stale-snapshot recoveryHistory remains verifiable; new authority starts at explicit boundary; old restore cannot fork node/sequenceM5/M8/G-WALLET-CONTRACTbefore production and every custody change
EV-USDC-CONTRACT-01Pinned Base USDC identitychain/address/ABI/EIP-712 domain/proxy implementation/runtime-code and event verificationConfigured native Base USDC is exact and drift is detected before paid readinessM5/G-WALLET-CONTRACTstartup, release, and dependency change
EV-USDC-CONTRACT-02EIP-3009 settlement truthforked-chain unused/settled/duplicate/expired/malformed/reorg fixturesFacilitator response cannot override canonical authorization, Transfer, receipt, block, payer, payee, amount, and action evidenceM5/G-WALLET-CONTRACTevery payment/reconciliation change
EV-ANCHOR-CONTRACT-01Anchor ABI/state/event/access invariantsSolidity unit/fuzz/invariant tests plus Go/Solidity anchor-ID vectorsUnauthorized, replayed, skipped, stale-predecessor, duplicate, and conflicting anchors fail; pause/rotation preserve headG-COMMIT-BASEevery contract change
EV-ANCHOR-CONTRACT-02Immutable deployment identityverified source/bytecode/compiler/constructor/ABI/runtime-code/deployment transaction readbackSigned deployment manifest reproduces exact immutable Base deployment identityG-COMMIT-BASEevery deployment
EV-ANCHOR-TX-01Bounded anchor transaction lifecycleSepolia canary with signer policy, nonce/replacement, fee caps, receipt loss, reorg, RPC outage, and backlog recoveryOne immutable intent per sequence reaches configured finality or halts without root/sequence mutation; IPFS/customer execution continuesG-COMMIT-BASEbefore mainnet and every submitter/finality change
EV-TREASURY-01Payment and refund reconciliationpayer→original-payee→treasury/refund chain and ledger reconciliationZero unexplained variance; refunds return only to original payer under dual approval and stable intent identityM5/G-WALLET-CONTRACT/M10daily and every refund

Consequential failure matrix

ScenarioRequired durable stateRecovery rule
Payment settled; execution failsPayment remains settled; effect is FAILED only when authoritative; refund is a separate decisionreconcile exact chain/action evidence; never resettle
Payment settlement outcome unknownBlock execution unless authoritative policy/evidence permits it; reserve liabilityreconcile the same authorization/transaction; no replacement payment
Effect succeeds; HTTP response lostReturn persisted action/output/receipt on replayno second dispatch or charge
Effect may succeed; state/receipt write failsPersist UNKNOWN or recover through effect-specific status probeINVOKE is not automatically repeated
Crash before dispatchSafe bounded retry after durable claim/recovery inspectionsame action, payment binding, and attempt history
Crash during deploy/version/rollback/deleteProbe stable runtime identity and converge under fencerecord every recovery attempt
Knative timeout or dependency outageClassify pre-effect versus ambiguous post-dispatchalert, contain, and respect retry class
Duplicate request/payment/callbackReturn/reconcile the existing canonical operationreject conflicting body or cross-action fingerprint
Backup/restore mismatchReadiness false; mutation disabledpreserve original and investigate; no silent repair
Receipt-chain or node-ID mismatchReadiness false; paid actions blockedrestore or repair through evidence-preserving procedure
IPFS publication unavailable or ambiguousCanonical operation continues; sealed bytes, expected CID, cursor, attempt, and retry state remain durableread back expected CID, then retry the exact same bytes; never reseal a different block for the same node/sequence
Conflicting evidence root or CID for one node/sequenceCommitment lane QUARANTINED; both trails preserved; canonical receipts unchangedstop evidence publication, investigate source/cutoff/encoding, and re-enter only through reviewed evidence-preserving repair
IPFS object unavailable after publicationEvidence availability alert and degraded evidence status; customer execution remains availablerestore/re-pin identical CAR/envelope from durable bytes or verified mirror and revalidate the same CID
Wrong or shared node-wallet roleMutation readiness false; active manifest and runtime mismatch preservedcorrect role binding or apply threshold-authorized manifest; never repurpose a customer/treasury/admin key
Contract wallet used where EOA-only recovery is supportedAction/payment rejected before settlement or effectuse supported EOA or separately implement ERC-1271; never pretend EOA recovery verifies a contract wallet
Payee rotates with outstanding challengesNew quotes use new payee; old authorization remains bound to original payeereconcile within bounded overlap; never redirect or rewrite signed authorization
Evidence/anchor signer unavailable or compromisedAffected signing lane stopped; last trusted sequence, attempts, and public key interval retainedoffline-authorized rotation/revocation; dispute affected interval append-only; never erase or silently re-sign
USDC or anchor contract identity driftsPaid/anchor readiness false; customer reads and canonical Badger preservedverify exact chain/proxy/runtime code/ABI/deployment and authorize a new pinned manifest if intentional
Anchor transaction dropped, replaced, reorged, or conflictingAll attempts retained; one immutable AnchorInput; no next sequence on conflictreconcile receipt, canonical block, event and head; rebroadcast identical payload only if canonical acceptance absent
Treasury/refund authority unavailable or refund ambiguousLiability reserved; stable refund intent and chain attempts retainedSafe-authorized exact-payer refund or reconciliation; never create a second intent blindly
Fail closed by affected authority. A wallet/contract/signing defect stops the affected paid, evidence, anchor, or administrative lane. It never authorizes a role substitution, secret recovery from logs, history rewrite, or duplicate transaction.
REQUIRED ONE-NODE FOUNDATION · NOT YET IMPLEMENTED

Seal evidence and publish it to IPFS.

The initial one-node product includes deterministic evidence blocks, IPFS publication, redundant availability, and independent verification. This work is now M7 on the active delivery path before operations and release rehearsal.

Required scope, honest state: the layer is not implemented in the current repository. Badger remains canonical for execution. IPFS distributes derived immutable evidence and must remain asynchronous to admission, payment, execution, receipt persistence, and recovery.

Required one-node evidence path

1 · Canonical cutofftransactionally consistent eligible terminal Badger records
2 · Deterministic leavesversioned, domain-separated, sanitized canonical bytes
3 · Merkle evidence blockstable order, root, sequence, previous commitment, coverage boundary
4 · IPFS packagedeterministic CAR/envelope → expected CID → publish and pin
5 · Independent readbacksecond endpoint/pin or mirror returns exact CID-addressed bytes
6 · Standalone verificationCID → bytes → leaves/proofs → recomputed root and coverage report
Not workload distribution. OCI images remain in the embedded Docker Distribution registry. This initial IPFS layer publishes sanitized audit evidence. IPFS distribution of customer workload artifacts remains deferred.

Required block contract

Header and coverage

  • schema_version, node_id, block_sequence
  • previous_block_commitment
  • transactionally consistent cutoff and deterministic eligibility rule
  • first/last stable record identity and leaf_count
  • merkle_algorithm_version and merkle_root
  • created_at metadata, never ordering authority

Envelope and privacy

  • ordered canonical public commitments
  • proof material or deterministic reconstruction data
  • domain-separated, length-framed leaf and node hashing
  • deterministic duplicate, empty-tree, and odd-leaf rules
  • no self-referential CID inside CID-addressed bytes
  • no secrets, signatures, payment authorizations, private inputs/outputs, or prohibited customer metadata

Durable one-node publication state

DRAFT → SEALED → PUBLISHED
          │          │
          ├─ PUBLISH_RETRYABLE
          └─ QUARANTINED on nondeterminism, privacy leak, or conflict
InvariantRequired behavior
Seal onceOne node/sequence has one cutoff, one immutable byte representation, one Merkle root, and one expected CID.
Retry exact bytesAmbiguous publication triggers expected-CID readback and retry of the identical CAR/envelope.
Persist before networkCutoff, sealed bytes, expected CID, attempts, availability observations, and quarantine state survive restart in Badger.
Remain asynchronousIPFS failure degrades evidence freshness but does not stop admission, payment, execution, receipts, or recovery.
Prove availabilityAt least two independently controlled retrieval paths reproduce the expected CID and Merkle root.
Quarantine conflictsConflicting roots/CIDs preserve both trails, stop publication, and never rewrite canonical receipts.

One-node activation gates

M7 · BUILD

Implement the foundation

Canonical projection, cutoff, Merkle blocks, durable publisher, IPFS package/pinning, independent readback, standalone verifier, privacy tests, and outage recovery.

G-IPFS · ACCEPT

Prove it operational

Deterministic vectors, crash recovery, independent retrieval, redundant availability, privacy proof, bounded lag, and zero impact on customer execution.

G-COMMIT-BASE · OPTIONAL LATER

CynderEvidenceAnchorV1

Separately authorize the exact immutable non-proxy contract, node-scoped anchor signer, admin Safe, pauser, runtime code/ABI, spend cap, sequence/head invariants, finality and reorg controls.

Evidence contracts

EV-COMMIT-01 · deterministic block, Merkle, and CID vectors

Independent runs over identical eligible records produce byte-identical leaves, tree, root, envelope, and expected CID.

EV-COMMIT-02 · IPFS round trip and redundant availability

Publish exact bytes and independently retrieve them through at least two controlled availability paths.

EV-COMMIT-04 · crash and ambiguity recovery

Crash at every local/network boundary and resume the same logical block and exact bytes.

EV-COMMIT-05 · independent verifier

A standalone verifier needs no cynderd API and reports root validity, record inclusion, sequence linkage, and coverage boundaries.

EV-COMMIT-PRIVACY · public evidence boundary

Forbidden-field fixtures prove private or secret material never enters public IPFS objects.

Contract interface boundary

AnchorInput: nodeId, identityEpoch, blockSequence, previousAnchor, identityManifestDigest, evidenceEnvelopeDigest, merkleRoot, contentCommitment, schemaVersion.

Contract: append-only per-node head, exact next sequence/predecessor, signer role, duplicate/conflict rejection, delayed signer rotation, pause-only emergency control, immutable deployment identity, events sufficient for independent reconstruction.

Read the complete normative ABI, custody, and transaction lifecycle →

Future layers remain separate

required one-node: Badger canonical records → deterministic evidence block → IPFS publication/pinning → independent verification
optional one-node enhancement: separately authorized Base root + CID anchor
future network: deterministic replicated state → CometBFT canonical blocks/AppHash → validators → authenticated snapshots → independent providers
Authority boundary: IPFS makes evidence content-addressed and retrievable; it does not order transactions, decide action finality, or validate source truth. Base may later timestamp a commitment. Only a future consensus system could make replicated finalized history canonical.
OPERATE WITH EXPLICIT BOUNDS

Operations and activation gates

G-WALLET-CONTRACT makes custody and external-contract truth mandatory before production. G-COMMIT-BASE remains a separate optional activation decision.

G-BASE

Technical baseline accepted

Requires: M0, EV-BASE-01, EV-UNIT-01

Accept source/state authority or return for correction.

G-LIFECYCLE

One-node lifecycle coherent

Requires: M1–M3, EV-ACC-01, EV-LIFE-01, EV-LIFE-02

Advance to parallel hardening or return to the broken component.

G-WALLET-CONTRACT

Wallet, custody, and Base-contract architecture adopted

Requires: M1, M5, EV-WALLET-01, EV-WALLET-02, EV-WALLET-03, EV-USDC-CONTRACT-01, EV-USDC-CONTRACT-02, EV-TREASURY-01, signed wallet/contract release manifest

Permit production hardening only when customer-wallet support, node-role separation, payee/treasury/refund custody, node identity binding, and external Base USDC identity are explicit and verified. This does not activate the optional anchor contract.

G-HARDENED

Safe, recoverable, observable, and externally verifiable

Requires: M4–M8, EV-FAIL-01, EV-PAY-01, EV-SEC-01, EV-COMMIT-01, EV-COMMIT-02, EV-COMMIT-04, EV-COMMIT-05, EV-COMMIT-PRIVACY, EV-RESTORE-01, EV-OPS-01, G-WALLET-CONTRACT

Permit exact-release rehearsal only after the one-node IPFS evidence layer is independently retrievable and recoverable.

G-IPFS

One-node IPFS evidence layer operational

Requires: M7, EV-COMMIT-01, EV-COMMIT-02, EV-COMMIT-04, EV-COMMIT-05, EV-COMMIT-PRIVACY

Accept the asynchronous evidence-publication layer as part of the one-node product or return to its originating contract/runtime defect. This does not activate Base anchoring or consensus.

G-PROD

Bounded production pilot authorized

Requires: M9, G-IPFS, EV-REL-01, named customer/workload/release/environment/caps/authority, G-WALLET-CONTRACT

Named human approves or declines one bounded paid pilot. Technical passage alone does not activate it.

G-SINGLE

Single-node product proven

Requires: M10, EV-PILOT-01, published evidence coverage for the pilot window, current recovery/security/accounting evidence

Operate, improve, bounded one-node expansion, or stop. Decentralization is not an automatic output.

G-COMMIT-BASE

Optional Base evidence anchor authorized

Requires: G-IPFS, EV-COMMIT-03, EV-ANCHOR-CONTRACT-01, EV-ANCHOR-CONTRACT-02, EV-ANCHOR-TX-01, signed deployment manifest, Base Sepolia proof, exact admin/pauser/anchor-signer custody, mainnet fee/finality/reorg/disable controls, separate human activation

Authorize or decline the exact immutable CynderEvidenceAnchorV1 deployment and bounded Base mainnet submitter. This remains optional and cannot block M7, G-IPFS, customer execution, or G-SINGLE.

G-PROD activation packet

Name customer, supported wallet type, active node-manifest digest/epoch, public role key IDs, payee/treasury Safe, refund/admin/pauser identities, exact Base USDC address and code/proxy identity, release/environment, IPFS endpoints, caps, SLO/RPO/RTO, evidence lag, and—only when enabled—anchor contract/code/ABI/signer/finality/spend policy.

Operational thresholds

MetricRequirementGate
Release identityExact source, image, chart, config, node, environment, Kubernetes/Knative, Base/USDC, facilitator, RPCM0/M8
Customer/workload boundOne named customer; one reviewed digest-pinned workload; exact scopesG-PROD
Duplicate consequential effects0M4–M10
Unexplained reconciliation variance0M5–M10
Critical unresolved custody/security findings0M6–M10
RPO / RTOTO ADOPT before G-PROD; provisional target ≤24h / ≤60mM8
Control-plane availabilityTO ADOPT before G-PROD; provisional pilot target 99% excluding approved maintenanceM8/M10
Critical alert delivery/acknowledgmentTO ADOPT before G-PROD; provisional pilot target 100%M8/M10
Spend/rate/concurrency/storage capsExact values required in activation packetG-PROD
Observation windowExact start/end and minimum operation count required in activation packetG-PROD/M10
Evidence publication lagTO ADOPT before G-IPFS; observable backlog with bounded age and no silent gapsM7/G-IPFS
IPFS evidence availabilityExpected CID retrievable through at least two independently controlled availability pathsM7/G-IPFS/M10
Evidence privacy violations0M7–M10
Conflicting root/CID for one node sequence0; any conflict quarantines publicationM7–M10
Wallet role collisions0M5/G-WALLET-CONTRACT
Runtime/manifest payee or signer mismatch0; affected paid/signing readiness falseM5–M10
USDC/anchor contract code drift0 unresolvedG-WALLET-CONTRACT/G-COMMIT-BASE
Unauthorized node/contract transaction0M5–M10
Anchor transactions in flightmaximum 1 per nodeG-COMMIT-BASE
Anchor signer balancebetween adopted minimum gas reserve and maximum blast-radius cap; 0 USDCG-COMMIT-BASE
Treasury/refund unexplained variance0M5/M10
Key rotation ageadopted per-role maximum; no expired active signerM5–M10

Containment and re-entry

Stop the affected lane on role collision, manifest/runtime mismatch, secret leakage, unauthorized transaction, contract drift, equivocation, signer ambiguity, stale restore, wrong payee/refund, or unexplained variance.

Re-enter only after: immutable evidence preserved; exact role/chain/contract/signing defect corrected; rotation/recovery or reconciliation completed; regression evidence refreshed; independent review signs off; and the bounded gate is explicitly reopened.

NORMATIVE ONE-NODE TECHNICAL SPEC

Node identity, wallets, custody, and Base contracts

This page defines what each identity can do, where its key lives, how it rotates, what is on-chain, and which parts exist today. “Node wallet” is not one universal key.

Current truth: customer Base EOAs, EIP-191 action recovery, x402/EIP-3009 settlement, configured payTo, and persistent CYNDER_NODE_ID exist. A cryptographic node manifest, node-held evidence/anchor signers, formal treasury/refund custody, and a Cynder-authored anchor contract do not yet exist.

Authority map

Customer EOAEIP-191 action + EIP-3009 payment · never node custody
x402 facilitatorsubmits customer authorization · not final chain authority
Native Base USDCrequired external contract · exact identity pinned
Payee/treasury Safe2-of-3 · receives USDC · no key in cynderd
customer authorization and chain evidence ↕
cynderd + Badger authorityTARGET BINDINGS NOT YET IMPLEMENTED
Logical node IDstable label + signed manifest chain
Evidence signerEd25519 · no funds · envelope only
Anchor submitteroptional · exact payload/contract/gas policy
Chain reconcilerUSDC/anchor events, receipts, canonical blocks, finality
optional commitment ↓
Anchor signerseparate low-balance EOA · gas only
CynderEvidenceAnchorV1immutable append-only registry · optional
Admin Safe + pauserrotation/registration vs pause-only authority

Wallet-role matrix

RoleTruth stateCustodyAuthorityMust not
CUSTOMER_ACTION_SIGNERIMPLEMENTED · EOA ONLYcustomer/agent outside cynderdEIP-191 action authorization and EIP-3009 payment authorization; signer must equal payeradminister node, sign evidence/anchors, receive node treasury authority
LOGICAL_NODE_IDIMPLEMENTED LABEL · CRYPTOGRAPHIC BINDING TARGETpersisted in canonical Badger and independently pinned genesis manifest digeststable attribution across pod/host/key rotationsbe treated as a private key, wallet address, hostname, pod UID, or IPFS peer ID
EVIDENCE_SIGNERTARGET · REQUIRED FOR SIGNED EVIDENCEnon-exportable Ed25519 signer preferred; isolated read-only key fallbacksign deterministic evidence envelopes onlyhold funds, sign EVM transactions, administer contracts, or own customer actions
ANCHOR_SIGNERTARGET · OPTIONAL BASE LAYERisolated low-balance secp256k1 signer with policy/allowlistsubmit exact finalized evidence commitments to one allowlisted contractbe payee, treasury, customer, evidence, or admin key
X402_PAYEE_TREASURY_REFUNDCONFIGURED ADDRESS · CUSTODY TARGETexternal Base Safe 2-of-3; no owner key in cynderdreceive Base USDC and execute treasury/refund movements under one explicit dual-approval Safe policysign customer actions, routine evidence, anchor transactions, or node/contract administration
NODE_ADMIN_CONTRACT_ADMINTARGEToffline/operator Base Safe 2-of-3; digest pinned independentlyapprove identity manifests, payee/signer changes, node replacement, contract node registration/rotationbe mounted in the pod or sign routine evidence/anchors
EMERGENCY_PAUSERTARGET · OPTIONAL CONTRACTseparately held hardware-backed operations key or dedicated Safe rolepause anchor submission onlyunpause, rotate signers, move treasury, or rewrite accepted anchors

Node identity manifest

Stable identity

CYNDER_NODE_ID remains an opaque stable 1–63 character identifier bound to one canonical Badger lineage; it is not a wallet or public-key fingerprint.

Schema: cynder-node-identity/v1

Canonicalization: RFC 8785 JCS; SHA-256 over the canonical manifest excluding admin_signatures; domain CYNDER_NODE_IDENTITY_V1\0

Contract node ID: nodeId = SHA-256(ASCII('CYNDER_NODE_ID_V1') || 0x00 || uint8(len(node_id)) || ASCII(node_id)); node_id must first pass the existing lowercase ASCII 1–63 character validator. The exact 32 bytes, not a hex string, enter AnchorInput and contract storage.

Genesis: The empty store accepts genesis only when its digest equals an independently configured CYNDER_NODE_GENESIS_DIGEST; writable Badger is not trust-on-first-use authority.

Manifest content

  • node_id
  • identity_epoch
  • manifest_sequence
  • previous_manifest_digest
  • genesis_manifest_digest
  • issued_at
  • effective_at
  • reason
  • status
  • admin_policy
  • role_keys
  • x402 payees
  • anchor policy
  • admin signatures

Epoch: Changes only for an offline-authorized node replacement or declared continuity break; routine signer/payee rotation increments manifest_sequence, not identity_epoch.

Required startup checks

CYNDER_NODE_ID
CYNDER_NODE_GENESIS_DIGEST
CYNDER_NODE_IDENTITY_MANIFEST_FILE
CYNDER_EVIDENCE_SIGNER_URI
CYNDER_ANCHOR_SIGNER_URI        # optional
CYNDER_X402_PAY_TO
Secret rule: configuration stores signer references and public identities only. Private keys, seeds, Safe owner material, customer authorizations, and raw signing requests never enter ConfigMaps, logs, Badger, IPFS objects, reports, or PVC backups.

Key custody

RoleAlgorithmOnlineFundsPreferred interfaceRotation
evidence signerEd25519yesnonenon-exportable signer URI/KMS/HSMoverlap plus dual-signed transition when available
anchor signersecp256k1only when Base anchoring enabledbounded ETH gas only; no USDCpolicy-controlled signer URI allowing exact chain/contract/functioncontract propose + delayed accept + test anchor + revoke old
x402 payee/treasury/refundSafe owner policyoutside cynderdUSDC revenueBase Safe 2-of-3signed manifest effective time plus bounded old-payee settlement overlap
node/contract adminSafe owner policynominimal admin gasseparate Base Safe 2-of-3old threshold approves new policy; both policies validate transition
emergency pausersecp256k1incident use onlybounded gasseparate hardware-backed keyadmin-only setPauser to a nonzero replacement

Contract inventory

REQUIRED EXTERNAL DEPENDENCY

Circle native USDC on Base

Network: eip155:8453

Address: 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913

Authority: Circle deployment/proxy; Cynder verifies exact network, proxy/implementation or code identity, EIP-3009 authorization state/events, Transfer event, and transaction receipt

Use: x402 settlement

Not: not node identity, evidence anchoring, escrow, staking, or governance

NORMATIVE TARGET · OPTIONAL · NOT IMPLEMENTED

CynderEvidenceAnchorV1

Network: Base Sepolia before Base mainnet

Address: unset until a verified immutable deployment manifest exists

Authority: node-scoped anchor signer; admin Safe manages node registration/rotation; separate pauser can only pause

Use: append-only root/CID commitments

Not: no x402 settlement, evidence storage, truth attestation, action execution, consensus, treasury, escrow, token, staking, or governance

Optional CynderEvidenceAnchorV1

Activation boundary: this design is normative so clients and evidence formats do not drift, but deployment and Base spending remain disabled until G-COMMIT-BASE. M7, IPFS, and customer execution do not depend on it.

Deployment policy

immutable non-proxy V1; new contract address and signed migration manifest for incompatible changes

exact Solidity compiler, optimizer settings, EVM target, source revision, ABI digest, deployment transaction/block, runtime code hash, constructor args, chain ID, and source verification recorded in a signed deployment manifest

Anchor identity

keccak256(abi.encode(keccak256('CYNDER_EVIDENCE_ANCHOR_V1'), block.chainid, address(this), all AnchorInput fields))

Decoded canonical CID bytes are committed as keccak256(cidBytes); the contract does not parse or store raw CIDs.

AnchorInput

nodeIdbytes32
identityEpochuint64
blockSequenceuint64
previousAnchorbytes32
identityManifestDigestbytes32
evidenceEnvelopeDigestbytes32
contentCommitmentbytes32 keccak256 of decoded canonical CID bytes
merkleRootbytes32
schemaVersionuint32

State and constructor

NodeState

latestAnchorbytes32
latestSequenceuint64
identityEpochuint64
signeraddress
activebool

PendingSigner

signeraddress
validAfteruint64 unix seconds
emptysigner=address(0) and validAfter=0; proposal overwrite is forbidden until accepted or admin-cancelled; acceptance/cancellation clears both fields atomically

Admin state

adminaddress
pendingAdminaddress
pendingAdminValidAfteruint64
pauseraddress
pausedbool

Constructor: constructor(address initialAdmin, address initialPauser, uint64 signerRotationDelay, uint64 adminRotationDelay); all addresses nonzero; delays immutable; deployer receives no implicit authority unless explicitly supplied as initialAdmin.

Authorization

submitAnchoronly the active node signer for input.nodeId
registerNodeonlyAdmin
setNodeActiveonlyAdmin
proposeNodeSigneronlyAdmin
acceptNodeSigneronly the pending signer after signerRotationDelay
cancelNodeSignerProposalonlyAdmin
advanceNodeEpochonlyAdmin while node inactive; new epoch=current+1 and expectedHead=current latestAnchor
setPauseronlyAdmin; nonzero replacement
proposeAdminonlyAdmin; nonzero pending admin and adminRotationDelay
acceptAdminonly pending admin after delay
pausepauser or admin
unpauseonlyAdmin

Interface

submitAnchor(AnchorInput) returns (bytes32 anchorId)
computeAnchorId(AnchorInput) view returns (bytes32)
getNodeState(bytes32) view returns (NodeState)
isAnchored(bytes32) view returns (bool)
registerNode(bytes32 nodeId,address initialSigner,uint64 initialEpoch)
setNodeActive(bytes32 nodeId,bool active)
proposeNodeSigner(bytes32 nodeId,address newSigner)
acceptNodeSigner(bytes32 nodeId)
cancelNodeSignerProposal(bytes32 nodeId)
advanceNodeEpoch(bytes32 nodeId,uint64 newEpoch,bytes32 expectedHead)
setPauser(address newPauser)
proposeAdmin(address newAdmin)
acceptAdmin()
pause()
unpause()

Storage

  • mapping(bytes32 nodeId => NodeState) nodes
  • mapping(bytes32 anchorId => bool) acceptedAnchors
  • mapping(bytes32 nodeId => PendingSigner) pendingSigners
  • address admin
  • address pendingAdmin
  • uint64 pendingAdminValidAfter
  • address pauser
  • bool paused
  • immutable uint64 signerRotationDelay
  • immutable uint64 adminRotationDelay

Events

  • AnchorAccepted(bytes32 indexed nodeId,uint64 indexed blockSequence,bytes32 indexed anchorId,bytes32 previousAnchor,uint64 identityEpoch,bytes32 identityManifestDigest,bytes32 evidenceEnvelopeDigest,bytes32 merkleRoot,bytes32 contentCommitment,uint32 schemaVersion,address submitter)
  • NodeRegistered(bytes32 indexed nodeId,address indexed signer,uint64 identityEpoch)
  • NodeActivationChanged(bytes32 indexed nodeId,bool active)
  • NodeSignerProposed(bytes32 indexed nodeId,address indexed currentSigner,address indexed proposedSigner,uint64 validAfter)
  • NodeSignerChanged(bytes32 indexed nodeId,address indexed previousSigner,address indexed newSigner)
  • NodeSignerProposalCancelled(bytes32 indexed nodeId,address indexed proposedSigner)
  • NodeEpochAdvanced(bytes32 indexed nodeId,uint64 previousEpoch,uint64 newEpoch,bytes32 expectedHead)
  • PauserChanged(address indexed previousPauser,address indexed newPauser)
  • AdminProposed(address indexed currentAdmin,address indexed proposedAdmin,uint64 validAfter)
  • AdminChanged(address indexed previousAdmin,address indexed newAdmin)
  • AnchoringPaused(address indexed actor)
  • AnchoringUnpaused(address indexed actor)

Submission invariants

Rotation and pause

Rotation: admin proposes nonzero signer; delay elapses; proposed signer proves possession by accepting; sequence/head never reset; compromised node is disabled before rotation

Pause: blocks submitAnchor only; reads/history/admin recovery remain available; IPFS evidence continues and ordered backlog accumulates

Signing and finality

Signing: anchor signer signs only exact chain, runtime-code-hash-pinned contract, submitAnchor selector, finalized local payload, bounded gas/fee/day; one transaction in flight per node

States: LOCAL_COMPLETESUBMISSION_PENDINGL2_INCLUDEDANCHOR_CONFIRMEDANCHOR_FINALREORGEDFAILED_RETRYABLEHALTED_CONFLICT

Reorg: rebroadcast identical immutable payload if receipt disappears and head reverted; preserve all attempt hashes; halt if canonical contract head conflicts

Transaction lifecycles

Customer payment

  • customer signs EIP-191 action digest
  • Cynder issues exact Base-USDC x402 challenge
  • customer signs EIP-3009 authorization
  • facilitator submits transfer
  • Cynder independently reconciles authorizationState, events, receipt, canonical block, payer/payee/amount/action
  • Badger records immutable original payee and settlement evidence

Optional evidence anchor

  • evidence body finalized and IPFS-pinned
  • signed evidence envelope sealed
  • anchor intent persisted before signing
  • chain/contract/code/function/payload/fee caps checked
  • one nonce/in-flight transaction assigned
  • broadcast and all replacement hashes persisted
  • receipt/canonical block/head/event/finality reconciled
  • next sequence admitted only after predecessor reaches operational finality

Payee rotation

  • admin manifest authorizes new payee and effective time
  • new challenges switch atomically
  • old payee retained only to reconcile pre-existing authorizations
  • historical receipts never rewritten
  • old authorizations cannot be redirected

Refund

target operator workflow: original payer and settled receipt determine destination/maximum amount; treasury Safe dual approval; stable refund intent ID; preflight and post-chain reconciliation prevent duplicate refund; no unrestricted refund key in cynderd

Compromise and anti-fork rules

Future multi-node separation

Future keys are new roles with independent custody and are never aliases or derivations of one-node keys.

P2P_TRANSPORTP2P_NODE_ASSERTIONVALIDATOR_CONSENSUSEXECUTOR_ATTESTATIONARTIFACT_PROVIDER
No consensus claim: per-node evidence signatures or Base anchors prove node-scoped provenance and ordering only. They are not validator votes, quorum certificates, or global transaction consensus.
CUSTODY AND NONCLAIMS

Reference

Exact revision lineage, source custody, economic invariants, and the boundary to future architecture.

Revision custody

Revision
rev_cynder_delivery_roadmap_node_wallet_contract_spec_v1_6_0_20260905
Parent
rev_cynder_delivery_roadmap_one_node_ipfs_foundation_v1_5_0_20260905
Whitepaper
rev_cynder_whitepaper_target_architecture_v0_5_3_20260905
Truth
PROVISIONAL
Implementation authorization
DOCUMENTATION_ONLY
Future-network authorization
NOT_GRANTED

Source dependencies

{
  "roadmapParent": {
    "kind": "roadmap_parent",
    "revisionId": "rev_cynder_delivery_roadmap_one_node_ipfs_foundation_v1_5_0_20260905",
    "indexSha256": "e4ac596ab514ae0c7345770c6bac26724869e225ab598d9c5fd31405842153ad",
    "workbookSha256": "dfbd8b953b7124703083381e327e46eb36e9edddcd11db71ec2ed2856076291f"
  },
  "whitepaper": {
    "kind": "whitepaper",
    "revisionId": "rev_cynder_whitepaper_target_architecture_v0_5_3_20260905",
    "sha256": "7188aa3fc17c35e20f1d66b1e4d58ece248a380b6e9e652a2b8e5cd4ec5cfb43"
  },
  "implementationBaseline": {
    "repository": "https://github.com/berryhill/cynder.git",
    "sourceRoot": "/home/silas/.hermes/workspace/codebases/cynder",
    "gitCommit": "134072ad266736c796ab7eac03679724a0af3a0f",
    "gitTree": "c16e1769e35a2c50c60487d428c7a8a31f86cede",
    "identityMethod": "Git commit and tree object IDs; exact source is retrievable from the repository",
    "workspaceObservation": "The canonical clone had uncommitted explorer/statistics work during roadmap assurance; those mutable bytes are not part of the pinned implementation baseline."
  }
}

Wallet and contract glossary

Customer walletExternal Base EOA signing its own Cynder action and x402 authorization.
Node IDStable non-secret logical identity; not a wallet or key.
Payee/treasuryExternal Safe receiving USDC and authorizing treasury/refund movements.
Evidence signerOnline no-funds Ed25519 key signing evidence envelopes only.
Anchor signerOptional low-balance EVM signer submitting one exact contract method.
AdminOffline/operator Safe authorizing manifests, registrations and rotations.
PauserSeparate authority able only to stop new anchors.
FacilitatorExternal x402 verifier/submitter; not node identity, custody, or final chain truth.

Contract registry

Native Base USDC

eip155:8453 · 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913

Required external EIP-3009 settlement dependency. Exact proxy/implementation or runtime-code identity must be verified by the release manifest.

CynderEvidenceAnchorV1

No address exists. Target is immutable/non-proxy and optional. A signed deployment manifest must name chain, address, transaction, block, runtime code hash, ABI digest, compiler/settings, admin, pauser, signer and finality policy.

Normative standards

CAIP-10EIP-191EIP-712EIP-3009RFC 8785 JCSEd25519ERC-1271: unsupported currentSafe: target custodyIPFS CID/multihash

Current implementation nonclaims: no node wallet, node identity manifest, Safe integration, evidence signer, anchor signer, refund executor, Cynder Solidity contract, anchor submitter, or anchor indexer exists in the pinned source. Current customer authorization is EOA-only.

Economic invariants

  • Gross collection is not protocol revenue.
  • Provider/service reimbursement is a liability.
  • Unknown costs are not zero.
  • Token treasury inventory is zero for runway analysis.
  • Token appreciation cannot be required for solvency.
  • The frozen model remains MODELED, not observed: at $3,500 weekly operating cost, both compared scenarios reach insolvency in week 71 and end near negative $291K; the candidate token does not repair the modeled service deficit.

Future boundary

REQUIRED ONE-NODE IPFS · FUTURE BASE/NETWORK

M7 and G-IPFS make deterministic evidence blocks, IPFS publication, redundant retrieval, and independent verification required before one-node release rehearsal. Badger remains canonical and IPFS remains asynchronous to customer execution.

Base root/CID anchoring is a separate optional gate. CometBFT, validators, provider markets, token, staking, liquidity, and governance remain future/conditional and outside required M0–M10 scope.

What source currently proves—and does not

Implemented foundations

  • Eight ActionTypes and strict payload validation
  • Canonical action digest, signature domain, durable state and receipt chain
  • x402/Base settlement verification and reconciliation foundations
  • Immutable versions, rollback, tombstones, replay, bounded recovery
  • Embedded tenant OCI registry, limits, retention records, and pins
  • Knative reconciliation with service accounts, quotas, limits, and NetworkPolicies
  • Single-replica/Recreate/RWO topology and quiesced snapshot helper

Not production proof

  • No complete real all-eight lifecycle evidence yet
  • No production signature/vulnerability enforcement or safe registry GC yet
  • No complete operator enrollment/revocation surface yet
  • No real isolated Kubernetes restore evidence yet
  • No production metrics, traces, alert rules, SLO, or capacity proof yet
  • No observed customer demand or measured service economics yet
  • No implemented node identity manifest, evidence signer, formal Safe payee/admin/refund custody, block builder, Merkle/IPFS publisher, Base anchor contract/submitter/indexer, or independent commitment verifier
  • Existing Base/x402 settlement support is not Base state-anchoring support
  • No live decentralized network, independent provider attestation, token, staking, or governance